File System Forensics

ATTN: Below is the assignment task; this is a hands-on assignment that requires a report. You will need the help of a sleuth kit and an image file. I have attached a zipped file that contains the image called “driveimage.dd”. Below is the assignment statement and question.
The best way to learn a tool, especially one that isnt well-documented, is to explore its functions. You are encouraged to use the Sleuth Kit
(Links to an external site.)
(TSK) to examine the file system image driveimage.dd
downloa
Copy and save TSK and driveimage.dd to your own computer. If you copy the file to your computer, verify the file copied correctly by its MD5 hash value:
86b0f076bfaf262b5b580dd327294d3b

Write a report describing each process used and your findings. Support your narrative with the output from the tools (not screenshots). To accomplish this, direct the output to a .txt file which can be saved (this file must be attached to your submission).
Your report should provide background information on the hardware and software used during the analysis and include the following:
The number of partitions on the drive.
The file systems for each partition
The cluster size for each file system
Where each file system starts and ends on the drive
Files you locate on each partition
Where you can find the information about where the file systems are located
Pick at least one file and provide details about it (use istat for this). Explain your findings in a way that would be easy for somebody with minimal technical experience to understand.

Last Completed Projects

topic title academic level Writer delivered